Skip to content

Conversation

@MariusStorhaug
Copy link
Member

Dependabot now checks for updates daily with a 7-day cooldown period, reducing noise while maintaining timely security updates. All GitHub Actions are pinned to specific commit SHAs with version comments for enhanced security and reproducibility.

Dependabot Configuration

Updated the schedule from weekly to daily with a cooldown of 7 days. This means Dependabot will check for updates daily but will wait 7 days after a new version is released before creating a PR, helping to avoid early adoption of potentially unstable releases.

schedule:
  interval: daily
cooldown:
  default-days: 7

Pinned Actions

All actions are now pinned to specific commit SHAs with version tag comments for traceability:

Action Version Commit SHA
actions/checkout v6.0.1 8e8c483db84b4bee98b60c0593521ed34d9990e8
super-linter/super-linter v8.3.2 d5b0a2ab116623730dd094f15ddc1b6b25bf7b99
PSModule/Auto-Release v1.9.5 eabd533035e2cb9822160f26f2eda584bd012356

@MariusStorhaug MariusStorhaug changed the title 🩹 Update dependabot schedule and pin actions to SHA 🩹[Patch]: Update dependabot schedule and pin actions to SHA Jan 22, 2026
@MariusStorhaug MariusStorhaug marked this pull request as ready for review January 22, 2026 14:29
@MariusStorhaug MariusStorhaug merged commit 40cd161 into main Jan 22, 2026
16 of 18 checks passed
@MariusStorhaug MariusStorhaug deleted the feature/update-dependabot-and-actions branch January 22, 2026 15:16
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants